2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-48085CRITICAL9.8Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component ...
CVE-2023-48084CRITICAL9.8Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.
CVE-2023-44709CRITICAL9.8PlutoSVG commit 336c02997277a1888e6ccbbbe674551a0582e5c4 and before was discovered to contain an integer overflow via th...
CVE-2023-49937CRITICAL9.8An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a ...
CVE-2023-49934CRITICAL9.8An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed versio...
CVE-2023-31546CRITICAL9.6Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature...
CVE-2023-40921CRITICAL9.8SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to ...
CVE-2023-6771CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Simple Student Attendance System 1.0...
CVE-2023-46727CRITICAL9.8GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI i...
CVE-2023-46726CRITICAL9.8GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP...
CVE-2023-6765CRITICAL9.8A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical....
CVE-2023-49363CRITICAL9.8Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php.
CVE-2023-6756CRITICAL9.8A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown functio...
CVE-2023-42495CRITICAL9.8 Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command (...
CVE-2023-6723CRITICAL9.8An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious fi...
CVE-2023-47577CRITICAL9.8An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no ch...
CVE-2023-50252CRITICAL9.8php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that reference...
CVE-2023-48225CRITICAL9.1Laf is a cloud development platform. Prior to version 1.0.0-beta.13, the control of LAF app enV is not strict enough, an...
CVE-2023-43364CRITICAL9.8main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.
CVE-2023-6593CRITICAL9.8 Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker t...
CVE-2023-46456CRITICAL9.8In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN c...
CVE-2023-46454CRITICAL9.8In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted p...
CVE-2023-48427CRITICAL9.8A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly v...
CVE-2023-41117CRITICAL9.8An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo...
CVE-2023-50424CRITICAL9.8SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, al...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now